Red HatCVE-2026-75569
Red Hat mce-operator-bundle. The build process fetches: remote code execution
High7.7CVE-2026-75569 · Published Aug 19, 2026 · updated Sep 8, 2026
A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks, such as commit pinning or signature verification. This allows a malicious actor with write access to the remote repository to inject and execute arbitrary code during the build. The consequence is a compromised build process, potentially leading to the distribution of malicious software.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-1357
- www.cve.org/CVERecord?id=CVE-2026-75569
- nvd.nist.gov/vuln/detail/CVE-2026-75569
- access.redhat.com/errata/RHSA-2026:59634
- access.redhat.com/errata/RHSA-2026:59636
- access.redhat.com/errata/RHSA-2026:59637
- access.redhat.com/errata/RHSA-2026:59638
- access.redhat.com/errata/RHSA-2026:59642
- access.redhat.com/errata/RHSA-2026:59643
- access.redhat.com/security/cve/CVE-2026-75569
- bugzilla.redhat.com/show_bug.cgi?id=2519849
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 19 | Red Hat search-indexer. This vulnerability: protection mechanism failure | Medium6.8 | No fix yet |
| Aug 19 | Red Hat acm-operator-bundle. The build process: untrusted functionality included | High8.0 | No fix yet |
| Aug 19 | Red Hat Advanced Cluster Management for Kubernetes 2: improper access control | Critical9.9 | No fix yet |
| Aug 19 | Red Hat: authentication bypass | Critical9.3 | No fix yet |
| Aug 19 | Red Hat volsync-addon-controller. This vulnerability: code injection | Medium6.2 | No fix yet |
| Aug 19 | Red Hat search-v2-operator. This vulnerability: privilege escalation | Critical9.1 | No fix yet |